| sharkey wrote: |
Is leaving phpinfo available dangerous?
I'm specifically refering to these fields:
_REQUEST["nuke_cpg_nuke_data"]
_REQUEST["user"]
_SERVER["HTTP_COOKIE"]
Do these only show the info from the browser looking or could someone use those fields to hijack a session?
Also this one would be scary but it's blank so it's cool
mysql.default_password no value no value |
your first question is yes it can show the path and other server varibles that an attacker can use